the example stopped at the core five and never mentioned the sidecars, so a fresh checkout gave no hint that transmission, slskd or the vault are configured at all. every value here is a placeholder. notes the two things that are easy to get wrong: transmission rejects an empty basic header, so user/pass must stay empty rather than blank-filled when the daemon has no rpc auth; and HEADSCALE_URL/API_KEY drive /api/vpn, not the officer-headscale sidecar, which deliberately reads neither. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
55 lines
2.9 KiB
Bash
55 lines
2.9 KiB
Bash
PORT=9000
|
|
JWT_SECRET="<generate with: openssl rand -base64 32>"
|
|
POSTGRES_URL="postgres://postgres:password@localhost:5432/officer"
|
|
MAIL_TRANSPORT="smtp://localhost:1025"
|
|
PUBLIC_URL=http://localhost:9000
|
|
|
|
# Guards (CORS origin checks, rate limits, password-strength rules) are ON unless this is set to
|
|
# "dev" or "development". Leave it unset or set it to "production" for a real deployment; only set
|
|
# it to "dev" on a local machine you trust, since that disables all three.
|
|
PUBLIC_BUILD_ENV=production
|
|
|
|
DATA_PATH=/path/to/data
|
|
OFFICER_ITEMS_DIR=/path/to/officer-items
|
|
HOME_DIR=/home/user
|
|
BROWSER_RELAY_PORT=18792
|
|
|
|
# ── Sidecars ────────────────────────────────────────────────────────────────────────────────────
|
|
# Each sidecar owns its upstream's credentials; the platform API is only a thin auth+forward proxy
|
|
# and never sees them. An unset upstream URL is not fatal — the sidecar logs a warning at boot and
|
|
# answers 503 until it is set, so you can run Officer with any subset of these configured.
|
|
|
|
# Transmission (officer-transmission). TRANSMISSION_USER/PASS are only needed if the daemon has RPC
|
|
# auth turned on; leave them empty otherwise, since Transmission rejects an empty Basic header.
|
|
# TRANSMISSION_RPC_PATH defaults to /transmission/rpc and only needs setting behind a reverse proxy
|
|
# that mounts the RPC endpoint somewhere else.
|
|
TRANSMISSION_URL=http://127.0.0.1:9091
|
|
TRANSMISSION_USER=
|
|
TRANSMISSION_PASS=
|
|
# TRANSMISSION_RPC_PATH=/transmission/rpc
|
|
|
|
# slskd (officer-slskd). The key is injected as X-API-Key on every forwarded request.
|
|
SLSKD_URL=http://127.0.0.1:5030
|
|
SLSKD_API_KEY="<slskd api key>"
|
|
|
|
# Vaultwarden (officer-vault). VAULT_STORE_KEY encrypts stored secrets at rest — any strong secret
|
|
# of 16+ chars works, and CHANGING IT MAKES EXISTING STORED SECRETS UNREADABLE.
|
|
VAULTWARDEN_URL=http://127.0.0.1:8222
|
|
VAULT_STORE_KEY="<generate with: openssl rand -base64 32>"
|
|
|
|
# Anthropic proxy (officer-anthropic-proxy). Defaults to 5051; it holds the API credential, which
|
|
# lives in the host env rather than here.
|
|
# ANTHROPIC_PROXY_PORT=5051
|
|
|
|
# ReClip — the self-hosted yt-dlp service the download-media capability talks to. Defaults to
|
|
# http://localhost:8899.
|
|
# RECLIP_URL=http://localhost:8899
|
|
|
|
# ── Headscale (/api/vpn) ────────────────────────────────────────────────────────────────────────
|
|
# These drive the /api/vpn router, NOT the officer-headscale sidecar. The sidecar deliberately reads
|
|
# neither, keeping its registered servers and their keys in Postgres so host env can never shadow
|
|
# one. Set these only if you use /api/vpn.
|
|
# HEADSCALE_URL=https://headscale.example.com
|
|
# HEADSCALE_API_KEY="<headscale admin api key>"
|
|
# HEADSCALE_USER=officer
|